CVE-2026-27220Disclosure(adobe / acrobat)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch adobe acrobat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • acrobat
  • acrobat_dc
  • acrobat_reader_dc
  • macos

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-10); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
acrobatacrobat_dcacrobat_reader_dcmacoswindows

1 version affected across 5 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-18: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 103-1003-1103-18
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-03-111
Patch1
2026-03-181
General1
Full discourse3 posts
  • dbugs@ptdbugs
    Patch

    Acrobat Reader | Use After Free (CWE-416) CVE: CVE-2026-27220 Vendor: Adobe Product: Acrobat Reader CVSS: 7.8 Credits: n/a Description: Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-27220 • https://helpx.adobe.com/security/products/acrobat/apsb26-26.html #dbugs_vuln

    Post summary

    Adobe Acrobat Reader is affected by a CVE‑2026‑27220 use‑after‑free flaw (CVSS 7.8); a patch is available via Adobe’s security advisory. The post provides technical details but no exploitation evidence.

    0001262
    556 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Adobe ❗ CVE-2026-27269 ❗ CVE-2026-27220 ❗ CVE-2026-21333 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-adobe-5/ https://t.co/mhbCIV7C5l

    Post summary

    The message lists three Adobe CVEs and directs readers to an external link for further details, but provides no additional technical or threat-related information.

    0000094
    6.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27220 Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execut… https://www.cve.org/CVERecord?id=CVE-2026-27220

    Post summary

    The text announces CVE-2026-27220, describing a Use‑After‑Free vulnerability in Acrobat Reader that could lead to arbitrary code execution, without providing any PoC, exploit, or patch information.

    0000093
    56.7K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeacrobat---
Appadobeacrobat_dc---
Appadobeacrobat_reader_dc---
OSapplemacos---
OSmicrosoftwindows---

Explore more